Don’t Leave Your Site At Risk
If your site is vulnerable to attack, you’re putting your business and your reputation at serious risk. Getting hacked can mean you’re locked out of your site, client data stolen, your website defaced or offline, and Google will penalise you.

Why take the risk?

Download and install Shield now for FREE so that you have the most powerful WordPress security system working for you and protecting your site.

The New Shield Pro

From November 2017, Shield Security now has a Pro version for those that need to take their Security to the next level.

Our Mission

All the great features of how Shield protects your sites and your customers data are set out below in detail, but there are a few things about us, that you should know first:

We’re on a mission to liberate people who manage websites from unnecessarily repetitive work, and by 2022 we want to
be saving our clients over 62.5 million hours per year (and we’d love you to join us in our quest)

We have three rules that apply to everything we do, and you’ll see these when you use our products or contact us for help:

We make everything as simple and easy-to-use as possible (and no simpler!).

We’re reliable – we make sure our products do what they promise.

We take ownership for resolving problems – we will solve the problem, or point you towards the solution.

So, read on for the detail, or start protecting yourself, your clients and your clients’ customers immediately by
downloading and installing Shield now

What makes the Shield different?

Powerful free security protection.

Easy-To-Setup User Interface.

It won’t break your website – you’ll never get that horrible,
pit-of-your stomach feeling you get with other security plugins when your website doesn’t load anymore.

Super Admin Security – the only WordPress Security Plugin that protects against tampering.

Exclusive membership to a private security group where you can learn more about WordPress security.

Super Admin Security Protection

The only WordPress security plugin with a WordPress-independent security key to protect itself. more info

Audit Trail Activity Monitor

With the Audit Trail you can review all major actions that have taken place on your WordPress site, by all users.

Firewall Protection

Blocks all web requests to the site that violate the firewall security rules! more info

SPAM and Comments Filtering

We have taken this functionality a level further and added the concept of unique, per-page visit, Comment Tokens.

Comment Tokens are unique keys that are created every time a page loads and they are uniquely generated based on 3 factors:

The visitors IP address.

The Page they are viewing

A unique, random number, generated at the time the page is loaded.

This is all handle automatically and your users will not be affected – they’ll still just have a checkbox like the original GASP plugin.

These comment tokens are then embedded in the comment form and must be presented to your WordPress site when a comment is posted. The plugin
will then examine the token, the IP address from which the comment is coming, and page upon which the comment is being posted. They must
all match before the comment is accepted.

Furthermore, we place a cooldown (i.e. you must wait X seconds before you can post using that token) and an expiration on these comment tokens.
The reasons for this are:

Cooldown means that a spambot cannot load a page, read the unique comment token and immediately re-post a comment to that page. It must wait
a while. This has the effect of slowing down the spambots, and, if the spambots get it wrong, they’ve wasted that token – as tokens can only
be used once.

Expirations mean that a spambot cannot get the token and use it whenever it likes, it must use it within the specfied time.

This all combines to make it much more difficult for spambots (and also human spammers as they have to now wait) to work their dirty magic 🙂

インストール

Note: When you enable the plugin, the firewall is not automatically turned on. This plugin contains various different sections of
protection for your site and you should choose which you need based on your own requirements.

Why do we do this? It’s simple: performance and optimization – there is no reason to automatically turn on features for people that don’t
need it as each site and set of requirements is different.

This plugin should install as any other WordPress.org respository plugin.

Browse to Plugins -> Add Plugin

Search: Shield

Click Install

Click to Activate.

A new menu item will appear on the left-hand side called ‘Shield’.

FAQ

Please see the dedicated help centre for details on features and some FAQs.

How does the Shield compare with other WordPress Security Plugins?

Easy – we’re just better! 😉

Firstly, we don’t modify a single core WordPress or web hosting file. This is important and explains why randomly you upgrade your security plugin and your site dies.

Ideally you shouldn’t use this along side other Anti-SPAM plugins or security plugins. If there is a feature you need, please feel free to suggest it in the support forums.

My server has a firewall, why do I need this plugin?

This plugin is an application layer firewall, not a server/network firewall. It is designed to interpret web calls to your site to
look for attempts to circumvent it and gain unauthorized access.

Your network firewall is designed to restrict access to your server based on certain types of network traffic. The Shield
is designed to restrict access to your site, based on certain type of web calls.

How does the IP Whitelist work?

Any IP address that is on the whitelist will not be subject to any of the firewall processing. This setting takes priority over all other settings.

Does the IP Whitelist support IP ranges?

Yes. To specify a range you use CIDR notation. E.g. ABC.DEF.GHJ.KMP/16

I want to black list an IP address, where can I do that?

You can’t. The plugin runs an automatic black list IP system so you don’t need to maintain any manual lists.

I’ve locked myself out from my own site!

This happens when any the following 3 conditions are met:

you have added your IP address to the firewall blacklist,

you have enabled 2 factor authentication and email doesn’t work on your site (and you haven’t chosen the override option)

You can completely turn OFF (and ON) the Shield by creating a special file in the plugin folder.

Here’s how:

Open up an FTP connection to your site, browse to the plugin folder /wp-content/plugins/wp-simple-firewall/

Create a new file in here called: “forceOff”.

Load any page on your WordPress site.

After this, you’ll find your Shield has been switched off.

If you want to turn the firewall on in the same way, create a file called “forceOn”.

Remember: If you leave one of these files on the server, it will override your on/off settings, so you should delete it when you no longer need it.

Which takes precedence… whitelist or blacklist?

Whitelist. So if you have the same address in both lists, it’ll be whitelisted and allowed to pass before the blacklist comes into effect.

What changes go into each version?

The changelog outlines the main changes for each release. We group changes by minor release “Series”. Changes in smaller “point” releases are highlighted
using (v.1) notation. So for example, version 4.4.1 will have changelog items appended with (v.1)

It is a comma-separated list of pages and parameters. A NEW LINE should be taken for each new page name and its associated parameters.

The first entry on each line (before the first comma) is the page name. The rest of the items on the line are the parameters.

The following are some simple examples to illustrate:

edit.php, featured

On the edit.php page, the parameter with the name ‘featured’ will be ignored.

admin.php, url, param01, password

Any parameters that are passed to the page ending in ‘admin.php’ with the names ‘url’, ‘param01’ and ‘password’ will
be excluded from the firewall processing.

*, url, param, password

Putting a star first means that these exclusions apply to all pages. So for every page that is accessed, all the parameters
that are url, param and password will be ignored by the firewall.

How does the login cooldown work?

When enabled the plugin will prevent more than 1 login attempt to your site every “so-many” seconds. So if you enable a login cooldown
of 60 seconds, only 1 login attempt will be processed every 60 seconds. If you login incorrectly, you wont be able to attempt another
login for a further 60 seconds.

The Automatic (Background) WordPress updates happens on a WordPress schedule – it doesn’t happen immediately when an update is detected.
You can either manually upgrade, or WordPress will handle it in due course.

How can I remove the WordPress admin footer message that displays my IP address?

You can add some custom code to your functions.php exactly as the following:

add_filter( 'icwp_wpsf_print_admin_ip_footer', '__return_false' );

How can I change the text/html in the Plugin Badge?

Use the following filter and return the HTML/Text you wish to display:

評価

I have been using this plugin since I started my blog over 6 months ago. I must say it is in the top 1% of the best security plugins I have ever used. There are many more options available than anything else out there. The options are just where you need them, the important places. Their firewall doesn't miss a thing and their lock-down of the account is the best I've seen. I truly recommend spending the $12 for the pro addition, if for no other reason than for the professional help you get. Their support is excellent, answered quickly and to the point. $12 for a plugin of this caliber is a must, nothing any better for this price anywhere.
They just updated their user interface, making it even better, more user friendly than ever. If you need to protect your website or blog, this is a MUST part of it to add.
Their traffic module gives you all the information you need for investigating / blocking / adding anyone you may want.
There is so much to say, but the best way to say it is why not download the free security plugin, try it and see all the options and great things and I an sure you will be running to get the Pro version for the small fee of just $12.
I don't know these people nor have any affiliation with their company. I found the plugin in the WordPress.org plugins. Feel free to contact me with any questions, I would be glad to try and answer them.
Kind regards,
Mark Taylor
CEO/President
Our World of Wealth
Billionaire Mailing List
Billionaire World News

New Control Panel is disorganised and some functions are only for premium users, including turning off email notifications which I never wanted in the first place. Looked in my server account and found a pile of lost notification emails to the wildcard account that I didn't need or care for, no way to turn them off.
I get that devs have to make money, but turning off the ability to stop notifications is a bit much. There is a Resolved thread in support which isn't definitive about a solution and the emails I have are recent.
The Login Page hiding was great, until the newer version made logging out not work properly, I'd have to go Back and then logout again, sometimes more than once.
I moved to WPS Hide Login which does just that, tried going back to Shield and some sites won't log out properly. I believe that between this and Wordfence with lots of settings config I should be covered. If the dev had left things alone and just updated...

I have been using Shield for a couple of weeks now and I am very impressed with the quality of the plugin and the features included in the free version.
I will soon install the plugin on other sites too and for some I will consider the premium option, which seems amazing value at $12/year!
Today when trying to resolve an issue caused by another plugin, Paul went above and beyond to make sure Shield remained usable.
Great quality, many features for free (with a premium version offering amazing value for money), excellent support equals 5 stars in my book 🙂

Compare with WordDefe***, or many other safety Plugins, Shield is the best security plugin I have tested.
Beside the excellent skill performance, the service also very very comfortable and quickly and professional.
I like Shield, So my plan is to upgrade the Pro for my other 30 websites. I also would write the test report and article in China Main Forums and other Public Media,like WeMedia.
At last, more information,or test the security performance, pls visit my website: wwww.genset.jx.cn

I have Shield Security installed on several client websites, and am extraordinarily pleased with its ease of use and comprehensive approach to site security.
Support is also excellent; the team responds quickly to questions and works diligently to resolve any issues.
And let us not forget the price! Shield Security is a superb bargain that does a superb job of securing your WordPress site.

I've been using Shield for over a year now. I manage about 20 instances of WordPress, plus some staging servers for each. And I now install Shield by default every time I get WP going. Shield is comprehensive in what it helps protect, its settings are easy to understand and configure, its protections are effective, and I’m completely happy with the peace of mind it offers once installed.
The free version is full-featured enough for many of our sites. But to top that off, to upgrade to pro at only $12/year is well worth the price for several of our sites that require an extra level of configuration or custom settings.
I've been in touch with their support team for two separate issues/requests. Their team is responsive, helpful, and willing to work through issues through to resolution. Whether the issue be on my end with my server config, or on their end with changes they might need to make to their code. Excellent, friendly, knowledgeable team.
Solid, easy to make recommendation to anyone wanting to further tighten up WordPress security.